← Back

CVE-2021-28113

nvd nist
Published: Apr 2, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Exploitability: 1.2 / Impact: 5.5
Source: NVD

Description

A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.

Affected (1)

Products: Okta: Access Gateway
1 product
Access Gateway
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2020.8.4

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.